Redhat
redhat
5,653 CVEs • 533 products
Products (533)
Click to collapseToggle
Products (533)
Click to collapse
CVEs (5,653)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The linux-2.4.21-mlock.patch in Red Hat Enterprise Linux 3 does not properly maintain the mlock page count when one process unlocks pages that belong to another process, which allows local users to mlock more memory than...Show more |
9Apple KdeLibtiff+6 more13Enterprise Linux Enterprise Linux DesktopFedora Core+10 moreApr 16, 2026 Dec 23, 2004 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, related to buffer overflows and integer overflows, allow remote attackers to execute arbitrary code via TIFF files. |
3Linux RedhatTrustix4Enterprise Linux Enterprise Linux DesktopLinux Kernel+1 moreApr 16, 2026 Dec 23, 2004 N/A· v4 N/A· v3 4.6 MEDIUM· v2 Certain USB drivers in the Linux 2.4 kernel use the copy_to_user function on uninitialized structures, which could allow local users to obtain sensitive information by reading memory that was not cleared from previous us...Show more |
2Linux Redhat3Fedora Core LinuxLinux KernelApr 16, 2026 Dec 15, 2004 N/A· v4 N/A· v3 2.1 LOW· v2 Memory leak in the ip_options_get function in the Linux kernel before 2.6.10 allows local users to cause a denial of service (memory consumption) by repeatedly calling the ip_cmsg_send function. |
2Linux Redhat3Fedora Core LinuxLinux KernelApr 16, 2026 Dec 15, 2004 N/A· v4 N/A· v3 2.1 LOW· v2 Integer overflow in the vc_resize function in the Linux kernel 2.4 and 2.6 before 2.6.10 allows local users to cause a denial of service (kernel crash) via a short new screen value, which leads to a buffer overflow. |
7Altlinux ConectivaDebian+4 more9Alt Linux Debian LinuxEnterprise Linux+6 moreApr 16, 2026 Dec 15, 2004 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Multiple vulnerabilities in Konqueror in KDE 3.3.1 and earlier (1) allow access to restricted Java classes via JavaScript and (2) do not properly restrict access to certain Java classes from the Java applet, which allows...Show more |
7Altlinux ConectivaDebian+4 more9Alt Linux Debian LinuxEnterprise Linux+6 moreApr 16, 2026 Dec 15, 2004 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Ethereal 0.9.0 through 0.10.7 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed SMB packet. |
7Altlinux ConectivaDebian+4 more9Alt Linux Debian LinuxEnterprise Linux+6 moreApr 16, 2026 Dec 15, 2004 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Unknown vulnerability in the DICOM dissector in Ethereal 0.10.4 through 0.10.7 allows remote attackers to cause a denial of service (application crash). |
4Ethereal Group GentooMandrakesoft+1 more5Enterprise Linux EtherealLinux+2 moreApr 16, 2026 Dec 6, 2004 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The SNMP dissector in Ethereal 0.8.15 through 0.10.4 allows remote attackers to cause a denial of service (process crash) via a (1) malformed or (2) missing community string, which causes an out-of-bounds read. |
4Ethereal Group GentooMandrakesoft+1 more5Enterprise Linux EtherealLinux+2 moreApr 16, 2026 Dec 6, 2004 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The SMB SID snooping capability in Ethereal 0.9.15 to 0.10.4 allows remote attackers to cause a denial of service (process crash) via a handle without a policy name, which causes a null dereference. |
4Ethereal Group GentooMandrakesoft+1 more5Enterprise Linux EtherealLinux+2 moreApr 16, 2026 Dec 6, 2004 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The iSNS dissector for Ethereal 0.10.3 through 0.10.4 allows remote attackers to cause a denial of service (process abort) via an integer overflow. |
Integer overflow in the ubsec_keysetup function for Linux Broadcom 5820 cryptonet driver allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a negative add_dsa_buf_bytes variab...Show more |
3Ipsec Tools KameRedhat4Enterprise Linux Enterprise Linux DesktopIpsec Tools+1 moreApr 16, 2026 Dec 6, 2004 N/A· v4 N/A· v3 10.0 HIGH· v2 The eay_check_x509cert function in KAME Racoon successfully verifies certificates even when OpenSSL validation fails, which could allow remote attackers to bypass authentication. |
7Conectiva GentooLinux+4 more9Enterprise Linux LinuxLinux+6 moreApr 16, 2026 Dec 6, 2004 N/A· v4 N/A· v3 2.1 LOW· v2 Unknown vulnerability in Linux kernel 2.x may allow local users to modify the group ID of files, such as NFS exported files in kernel 2.4. |
2Avaya Redhat4Cvlan Enterprise LinuxEnterprise Linux Desktop+1 moreApr 16, 2026 Nov 23, 2004 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple extfs backend scripts for GNOME virtual file system (VFS) before 1.0.1 may allow remote attackers to perform certain unauthorized actions via a gnome-vfs URI. |
3Linux RedhatTrustix3Fedora Core Linux KernelSecure LinuxApr 16, 2026 Nov 23, 2004 N/A· v4 N/A· v3 2.1 LOW· v2 Linux kernel does not properly convert 64-bit file offset pointers to 32 bits, which allows local users to access portions of kernel memory. |
244d AppleAvaya+21 more65Aaa Server Access RegistrarApache Based Web Server+62 moreApr 16, 2026 Nov 23, 2004 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a de...Show more |
234d AppleAvaya+20 more66Aaa Server Access RegistrarApache Based Web Server+63 moreApr 16, 2026 Nov 23, 2004 N/A· v4 N/A· v3 5.0 MEDIUM· v2 OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool. |
234d AppleAvaya+20 more66Aaa Server Access RegistrarApache Based Web Server+63 moreApr 16, 2026 Nov 23, 2004 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference. |
1Redhat 2Enterprise Linux Enterprise Linux DesktopApr 16, 2026 Oct 20, 2004 N/A· v4 N/A· v3 7.5 HIGH· v2 Unknown vulnerability in redhat-config-nfs before 1.0.13, when shares are exported to multiple hosts, can produce incorrect permissions and prevent the all_squash option from being applied. |